Privacy Policy

Privacy Policy

We don't like small print any more than you do, so here's what actually happens with your information when you spend time on this site: no jargon, no funny business.

Just Browsing?

If you're only here to look around, here's the good news: this site doesn't require an account, and it doesn't create one for you in the background. A handful of things get saved as you poke around, and all of them live in your browser's localStorage — on your own device, not on a server:

  • Your theme choice (dark or light mode), so the site remembers which one you picked.
  • Your “Saved For Later” wishlist — anything you heart on the shop page.
  • Your cart — which goods, which sizes, how many, and any gift message or recipient email you've typed into a gift card.
  • Recently viewed items, so the carousel at the bottom of the shop can show you where you've been (the last eight, by product ID).
  • A gift card code you've applied to your cart, along with its balance, and your Alt-Points total.
  • Your language choice, if you use the translation tool (stored locally in localStorage['yl-lang'], zero cookies).

None of that is sent anywhere while you're browsing. The cart is the one to know about: it stays on your device right up until you click Checkout, at which point its contents go to our checkout service so it can build your payment page. Clear your browser data, or switch devices or browsers, and all of it resets, because it was never anywhere but your own machine to begin with.


What We Collect Directly

Every form on this site is listed here, along with where what you type actually goes. Nothing on this list is optional to mention and nothing is left off it:

  • Contact form (on the Contact page) — your name, email address and message. Delivered to our inbox by Formspree (opens in new tab), a form-forwarding service.
  • Review form (at the bottom of the Shop page, on the Reviews page, and on every product page) — your name or handle, an optional email address, which product (or the whole shop), a star rating and your review. Also delivered through Formspree. We read them by hand and publish approved ones; the email address is never published.
  • Restock & launch alerts (the “Notify me when it's back” box in the shop) — your email address and which item you asked about. That goes to our small service on Cloudflare Workers (opens in new tab), which emails it to us through Resend (opens in new tab). Nothing is kept once that email is sent.
  • Market-date reminders (the “Email me the next market date” box on the Events page) — your email address, and nothing else. It is stored by that same small service on Cloudflare Workers, which uses it for exactly one thing: one email the day before each market we're at, sent through Resend. Every one of those emails has an unsubscribe link in it, and unsubscribing from any email we send stops these too.
  • Order lookup (“Track Order Status” in the shop, on the order confirmation page and on the Order Status page) — your order reference and the email you used at checkout. Our Cloudflare service checks them against Stripe and shows you your order's status; it stores neither.
  • Gift card balance check (in the shop) — the gift card code you type. Looked up by the same Cloudflare service, which holds gift card balances; the code is not kept anywhere else.
  • Gift card recipient details — if you buy a gift card for someone, the recipient's email address, your name and your message travel with the order through checkout so the code can be emailed to them.
  • Newsletter signup (in the footer, and on the welcome page) — your email address, held by our newsletter provider. More on that below.
  • Birthday club (optional, on the order confirmation page) — the month and day of your birthday only, never the year, held with your newsletter subscription so we can send a birthday treat. We deliberately do not collect your birth year or any other date.
  • Reaction reports (the Report a Reaction page) — what you tell us about a reaction to something we made: the product and lot, when you used it, what happened, your name, email, an optional phone number, and an optional age range and sex. Federal law requires a body-care label to carry a way to report this, and requires us to keep the report. More on it just below.
  • Live chat — if you open the chat bubble and start a conversation, whatever you type in it (and, if you offer it, your name and email) is held by our chat provider. More on that below too.

There is no account system, no login, and no profile being assembled anywhere. What you send us is what we have.

This site sells body care and apparel to adults and is not directed at children. We do not knowingly collect personal information from anyone under 13; if you believe a child has sent us something, email us and we will delete it.


Reaction Reports

A reaction report is the one thing on this page we are not free to throw away. The Modernization of Cosmetics Regulation Act requires every body-care label to carry a way for you to report an adverse event — that is what the Report a Reaction page is — and it requires us to keep what you send. So we do: every reaction report is kept for at least three years from the day it arrives — the period the law sets for a business our size. Nothing deletes them on a timer, so in practice it is longer; a record we still have is never the problem.

What you type there goes to the same small service of ours on Cloudflare Workers (opens in new tab) that handles checkout, which stores it in a database on Cloudflare and emails a copy to us through Resend (opens in new tab). Resend delivers that email and your acknowledgement; it does not keep a copy on our behalf. We do not store the IP address you sent it from — only a one-way scramble of it, so we can spot a flood of junk without holding the address itself.

We share reaction reports with the FDA only when the law requires it. That means a serious adverse event — death, a life-threatening reaction, hospitalisation, lasting disability, a birth defect, an infection, significant disfigurement, or a medical or surgical procedure to prevent one of those — which we have to report to the FDA within 15 business days on the MedWatch form. Nothing else goes to them, nothing goes to anyone else, and none of it is ever used for marketing, sold, or fed to any analytics tool. That page fires no analytics events at all — it is counted as a page view like any other page, and nothing about the report, including its reference number, goes with it.

You can ask us what we hold on you and, outside what the law makes us keep, ask us to delete it — see “Questions, Or Want Something Deleted?” below.


When You Buy Something

Your cart lives right here on this site, but payment itself is handled by Stripe (opens in new tab), a third-party payment processor. When you check out, you're taken to a payment page hosted by Stripe -- your card details are entered there, not on our site, and never pass through or get stored on our servers. That means your name, shipping address, email, and payment details are collected and stored by Stripe, not by us directly. We see your order information so we can make and ship your goods, but the sensitive handling (card numbers, etc.) never touches our own servers because we don't run any.

Getting you to that Stripe page takes two pieces of plumbing, and both see your order on the way through. The Checkout button posts your cart to a small service of ours running on Cloudflare Workers (opens in new tab), which re-prices everything against our own catalogue and asks Stripe for a payment page. After you pay, Stripe notifies that same Cloudflare service, which is what issues gift card codes and keeps track of their balances (in a small database on Cloudflare that holds only the codes, their balances and a record of which Stripe events it has already handled). If your order includes a gift card, that service sends the code by email through Resend (opens in new tab) — to you, or to the recipient address you gave us.

For the full details on how Stripe handles your data, read Stripe's own privacy policy (opens in new tab): they're the ones actually storing and processing that information, so they're the most accurate source on it.


Our Email Updates

If you sign up for our email updates, the email address you provide is stored by Kit (opens in new tab) (the service formerly called ConvertKit), and used only to send you the updates you asked for. The signup form posts straight to Kit, so your address goes to them directly. We don't sell it or share it with anyone outside of running that newsletter, and you can unsubscribe any time using the link included in any email we send.


Shopping On Etsy

Some of our goods are also listed on our Etsy shop (opens in new tab), and this site links out there as another way to buy. Once you click through to Etsy, you're on Etsy's platform and subject to Etsy's own privacy policy (opens in new tab), which is separate from this one and out of our hands.


Fonts

The typefaces on this site are served from our own domain, so loading a page does not send a font request to Google or to any other font provider. No font-related third parties are involved.


Cookies & Analytics

The browser storage this site uses is the functional kind, listed in full under “Just Browsing?” above: your theme, your wishlist, your cart, your recently viewed items, an applied gift card, and your language choice (in local storage). None of it is used for tracking or advertising, and none of it sets a cookie.

Analytics. This site runs Umami (opens in new tab) for analytics. Umami is cookieless, doesn't collect or store personal data, doesn't fingerprint your device, and can't track you across other websites — it counts anonymous, aggregate activity: which pages get looked at, which products get added to a cart or saved to a wishlist, which quiz answer came out, when a checkout is started and whether it went through, and the total of a completed order. Never who.

Two specifics worth spelling out. We strip the query string off every web address before it is counted, so the order reference in a receipt link, the address in a mailing-list link, and the reference number on a reaction report are never sent — and what we add back is a short, fixed list: the campaign tag on a link we published ourselves, so we can tell whether a post or a market QR code brought anyone here; the shop filter you arrived on, like “apparel” or “eczema”; and the click tag a social network or ad network attaches to its own links. That last one is a random string standing for one click, not for you, and it is never joined to anything else. And our search box reports only how long a search was and whether it found anything, never what you typed.

Two things we would rather say plainly than leave you to find out. We do not act on the browser’s old “Do Not Track” setting: the browsers that shipped it have since retired it, and it was never a consent signal for counting that stores nothing about a person. What we do instead is not collect the data in the first place — everything above describes what is actually sent, and there is nothing else. And the counter is loaded from the analytics company directly, the ordinary way — but if something on your end blocks that, we load it from this site’s own web address instead, so a blocker that works by blocking other companies’ domains will not stop the count. What is counted is the same either way, and it is only ever the aggregate activity described above. If we ever switch analytics off, nothing loads and nothing is counted.

Live chat. The chat bubble in the corner is Tawk.to (opens in new tab), and it is live on every page of this site, product pages included — the one exception is the offline fallback page you only see when your connection drops. Unlike the rest of what's here, it loads its own script and sets its own cookies (it uses them to recognize a returning visitor and keep a conversation together), and it can see the page you're on. Anything you type into the chat is held by Tawk.to as well as reaching us.

Translation. Translations are self-hosted and run locally in your browser with zero cookies, zero third-party scripts, and zero network requests to Google or any external service. Your language preference is saved solely in your browser's local storage (localStorage['yl-lang']).

The other third-party services embedded here — Stripe during checkout, and Etsy once you click through — may set their own cookies or use their own tracking as part of how they operate. Those are governed by those companies' own policies.


Everyone Who Touches Your Data

We're one person and a workshop, so almost everything here is somebody else's service doing a job we can't do ourselves. This is the whole list, and what each one is for:

If that list ever changes, this page changes with it. That's the deal.


Children's Privacy

This site and everything we sell is intended for adults, not for children. It isn't directed at anyone under 13, and we don't knowingly collect information from kids.


Your Rights

We're a tiny handmade business, not a compliance department, so we won't claim any formal certification here. But if you're in the EU, the UK, California, or anywhere else with specific data rights you'd like to exercise (access, correction, deletion, whatever it may be), email us and we'll do our honest best to help.


Questions, Or Want Something Deleted?

There's no self-serve portal or automated system here. Just us. If you have questions about this policy, want to know what we have on file, or want your email address (or anything else we hold) deleted, email y.allternative.living@gmail.com and we'll take care of it by hand.


Changes To This Policy

If how this site handles data ever changes (a new tool, a new feature, actual analytics down the line), we'll update this page to keep it accurate rather than let it go stale.

Last updated: September 2, 2026

Keep Shopping

Back To The Good Stuff

Questions about any of this? Reach out any time. Otherwise, head on back to the homepage or go treat yourself.

Shop The Collection

Popular Searches